axio - kn

test

Posts by Richard Caralli:

Navigating New Healthcare Cybersecurity Regulations: What You Need to Know

Navigating New Healthcare Cybersecurity Regulations: What You Need to Know

With cyber threats evolving rapidly and healthcare systems increasingly reliant on digital infrastructure, protecting patient data is more important than ever. The Department of Health and Human Services’ (HHS) proposed updates to the HIPAA Security Rule signal a move toward stricter, more proactive security measures—ones that demand immediate attention from healthcare providers and their partners.

Transforming Cyber Risk Management for Critical Infrastructure with CRQ

Transforming Cyber Risk Management for Critical Infrastructure with CRQ

In today’s high-stakes cybersecurity environment, critical infrastructure organizations are increasingly targeted by cyber threats capable of causing widespread operational and societal disruption. Traditional approaches to cyber risk management, built around qualitative scoring, fall short in providing the precision and context required to address these modern challenges. In a recent CyberScoop article, I  explore why a transformative shift toward Cyber Risk Quantification (CRQ) is essential to empower organizations with actionable insights and align cybersecurity strategies with real-world financial and operational priorities.

SEC Rule Poses New Challenges for CISOs

SEC Rule Poses New Challenges for CISOs

In July 2023, the Securities and Exchange Commission (SEC) adopted rules requiring publicly-traded companies to disclose material cybersecurity incidents and to report on their cybersecurity risk management, strategy, and governance activities on an annual basis beginning in December 2023.  For some organizations, this is simply a recalibration of good cybersecurity risk management practices already in place. For others, improvements in the way cybersecurity risk is managed, analyzed, mitigated, and reported on will be on the horizon.  At the center of this new requirement is the changing and evolving role of the CISO—which faces a make-or-break moment.

PAM is a Process, Not Just a Tool

PAM is a Process, Not Just a Tool

In an official statement, Uber confirmed that it responded to a cybersecurity incident, the result of which is still under investigation. Based on reports from cybersecurity media, the attacker appeared to obtain a third-party contractor’s access credentials on the dark web and attempted to use them to gain access to Uber’s network and systems. On each successive attempt, the contractor was presented with a multi-factor approval request, which was ultimately accepted. The contractor’s credentials reportedly gave the hacker elevated privileges, which in some reports, included access to a network share of PowerShell scripts that contained administrative credentials with access to AWS and other key technology platforms.

How to Navigate the Cybersecurity Framework Landscape

How to Navigate the Cybersecurity Framework Landscape

With the recent high-profile ransomware attack on Colonial Pipeline Co., more companies than ever before have started to think about the potentially devastating consequences of cyber attacks and how to best protect themselves from them. Cyber attacks that affect critical infrastructure can not only paralyze the targeted organization, but often have downstream impacts on the health and safety of citizens, economic stability, and supply chains to name a few.